Class DefaultBearerTokenResolver

java.lang.Object
com.codename1.backend.security.oauth2.server.resource.DefaultBearerTokenResolver
All Implemented Interfaces:
BearerTokenResolver

public final class DefaultBearerTokenResolver extends Object implements BearerTokenResolver

Finds the token in the Authorization: Bearer header.

A token in the address -- ?access_token=... -- is read only when setAllowUriQueryParameter(boolean) says so, and then on a GET alone. An address is what ends up in access logs, browser history and the Referer of the next page, which is no place for a credential; the switch exists for the client that cannot set a header, an EventSource or a download link.

A request with a token in both places is refused rather than guessed at.

  • Constructor Details

    • DefaultBearerTokenResolver

      public DefaultBearerTokenResolver()
  • Method Details

    • setAllowUriQueryParameter

      public void setAllowUriQueryParameter(boolean allowUriQueryParameter)
      Whether access_token in the query of a GET is read; not, unless set.
    • setBearerTokenHeaderName

      public void setBearerTokenHeaderName(String bearerTokenHeaderName)
      The header the token is read from; Authorization unless set. For a server behind a proxy that keeps Authorization for itself.
    • resolve

      public String resolve(HttpServer.Request request)
      Description copied from interface: BearerTokenResolver

      The token, or null when the request carries none.

      • OAuth2AuthenticationException: when the request carries one that is malformed, or more than one
      Specified by:
      resolve in interface BearerTokenResolver